Escape HTML

This commit is contained in:
Naoki Takezoe
2018-05-28 15:42:32 +09:00
parent d064ca85fb
commit c65c3e2c49

View File

@@ -9,7 +9,7 @@ import gitbucket.core.model.Account
import gitbucket.core.service._ import gitbucket.core.service._
import gitbucket.core.util.Implicits._ import gitbucket.core.util.Implicits._
import gitbucket.core.util.SyntaxSugars._ import gitbucket.core.util.SyntaxSugars._
import gitbucket.core.util.{Keys, LDAPUtil, ReferrerAuthenticator, UsersAuthenticator} import gitbucket.core.util._
import org.scalatra.Ok import org.scalatra.Ok
import org.scalatra.forms._ import org.scalatra.forms._
@@ -208,7 +208,7 @@ trait IndexControllerBase extends ControllerBase {
} }
.map { t => .map { t =>
Map( Map(
"label" -> s"<b>@${t.userName}</b> ${t.fullName}", "label" -> s"<b>@${StringUtil.escapeHtml(t.userName)}</b> ${StringUtil.escapeHtml(t.fullName)}",
"value" -> t.userName "value" -> t.userName
) )
} }